ip-address 是一个用于在 JavaScript 中解析和操作 IPv4 和 IPv6 地址的库。在版本 10.7.1 之前, 构造函数、 方法以及 中的解析代码会接受无长度限制的字符串,并将包含无效字符的字符串通过 正则表达式匹配后,展开为巨大的诊断输出。只有当应用程序接收非常大型的、由攻击者控制的字段,并在将其传递给 解析之前未施加长度限制时,才会产生实质性影响。 通常情况下,URL 和 HTTP 头部的长度限制,以及常见 body-parser 的默认配置,会对该漏洞的影响范围起到约束作用;常见的默认
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| beaugunderson | ip-address | < 10.7.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| beaugunderson | ip-address | < 10.7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101910 | 6.9 MEDIUM | ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SS |
| CVE-2026-101913 | 6.3 MEDIUM | ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SS |
| CVE-2026-101912 | 6.3 MEDIUM | ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as i |
No comments yet